Memory corruption in Quagga - CVE-2018-5378
Published: February 19, 2018
Vulnerability identifier: #VU10655
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5378
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the Quagga BGP daemon due to failure to properly bounds check data sent with a NOTIFY to a peer by the Quagga BGP daemon, bgpd. A remote attacker can send specially crafted input and cause the bgpd process or the daemon to crash.
The weakness exists in the Quagga BGP daemon due to failure to properly bounds check data sent with a NOTIFY to a peer by the Quagga BGP daemon, bgpd. A remote attacker can send specially crafted input and cause the bgpd process or the daemon to crash.
Affected software
Quagga
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE OpenStack Cloud
SUSE Linux
Fedora
libfpm_pb0-debuginfo
libzebra1
quagga-debugsource
libfpm_pb0
libzebra1-debuginfo
libospfapiclient0
quagga-debuginfo
libquagga_pb0-debuginfo
libospf0
libospfapiclient0-debuginfo
libquagga_pb0
quagga
libospf0-debuginfo
quagga-devel
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE OpenStack Cloud
SUSE Linux
Fedora
libfpm_pb0-debuginfo
libzebra1
quagga-debugsource
libfpm_pb0
libzebra1-debuginfo
libospfapiclient0
quagga-debuginfo
libquagga_pb0-debuginfo
libospf0
libospfapiclient0-debuginfo
libquagga_pb0
quagga
libospf0-debuginfo
quagga-devel
How to mitigate CVE-2018-5378
Update to version 1.2.3.
libfpm_pb0-debuginfo - update to 1.1.1-17.13.1
libzebra1 - update to 1.1.1-17.13.1
quagga-debugsource - update to 1.1.1-17.13.1
libfpm_pb0 - update to 1.1.1-17.13.1
libzebra1-debuginfo - update to 1.1.1-17.13.1
libospfapiclient0 - update to 1.1.1-17.13.1
quagga-debuginfo - update to 1.1.1-17.13.1
libquagga_pb0-debuginfo - update to 1.1.1-17.13.1
libospf0 - update to 1.1.1-17.13.1
libospfapiclient0-debuginfo - update to 1.1.1-17.13.1
libquagga_pb0 - update to 1.1.1-17.13.1
quagga - update to 1.1.1-17.13.1
libospf0-debuginfo - update to 1.1.1-17.13.1
quagga-devel - update to 1.1.1-17.13.1
quagga - addressed in versions 1.2.2-2.fc26, 1.2.2-2.fc27
libzebra1 - update to 1.1.1-17.13.1
quagga-debugsource - update to 1.1.1-17.13.1
libfpm_pb0 - update to 1.1.1-17.13.1
libzebra1-debuginfo - update to 1.1.1-17.13.1
libospfapiclient0 - update to 1.1.1-17.13.1
quagga-debuginfo - update to 1.1.1-17.13.1
libquagga_pb0-debuginfo - update to 1.1.1-17.13.1
libospf0 - update to 1.1.1-17.13.1
libospfapiclient0-debuginfo - update to 1.1.1-17.13.1
libquagga_pb0 - update to 1.1.1-17.13.1
quagga - update to 1.1.1-17.13.1
libospf0-debuginfo - update to 1.1.1-17.13.1
quagga-devel - update to 1.1.1-17.13.1
quagga - addressed in versions 1.2.2-2.fc26, 1.2.2-2.fc27